VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (12,807)

page 581 of 641
  • CVE-2019-20107HigMar 5, 2020
    risk 0.00cvss 8.8epss 0.02

    Multiple SQL injection vulnerabilities in TestLink through 1.9.19 allows remote authenticated users to execute arbitrary SQL commands via the (1) tproject_id parameter to keywordsView.php; the (2) req_spec_id parameter to reqSpecCompareRevisions.php; the (3) requirement_id…

  • CVE-2020-8841HigFeb 10, 2020
    risk 0.00cvss 8.8epss 0.01

    An issue was discovered in TestLink 1.9.19. The relation_type parameter of the lib/requirements/reqSearch.php endpoint is vulnerable to authenticated SQL Injection.

  • CVE-2019-15300HigNov 27, 2019
    risk 0.00cvss 8.8epss 0.02

    A problem was found in Centreon Web through 19.04.3. An authenticated SQL injection is present in the page include/Administration/parameters/ldap/xml/ldap_host.php. The arId parameter is not properly filtered before being passed to the SQL query.

  • CVE-2019-19250CriNov 25, 2019
    risk 0.00cvss 9.8epss 0.01

    OpenTrade before 2019-11-23 allows SQL injection, related to server/modules/api/v1.js and server/utils.js.

  • CVE-2019-18413LowOct 24, 2019
    risk 0.00cvss 3.7epss 0.02

    In TypeStack class-validator 0.10.2, validate() input validation can be bypassed because certain internal attributes can be overwritten via a conflicting name. Even though there is an optional forbidUnknownValues parameter that can be used to reduce the risk of this bypass, this…

  • CVE-2018-21022HigOct 8, 2019
    risk 0.00cvss 8.8epss 0.02

    makeXML_ListServices.php in Centreon Web before 2.8.28 allows attackers to perform SQL injections via the host_id parameter.

  • CVE-2018-21021HigOct 8, 2019
    risk 0.00cvss 8.8epss 0.02

    img_gantt.php in Centreon Web before 2.8.27 allows attackers to perform SQL injections via the host_id parameter.

  • CVE-2019-17197CriOct 5, 2019
    risk 0.00cvss 9.8epss 0.01

    OpenEMR through 5.0.2 has SQL Injection in the Lifestyle demographic filter criteria in library/clinical_rules.php that affects library/patient.inc.

  • CVE-2019-15533CriAug 26, 2019
    risk 0.00cvss 9.8epss 0.01

    XENFCoreSharp before 2019-07-16 allows SQL injection in web/verify.php.

  • CVE-2019-15558CriAug 26, 2019
    risk 0.00cvss 9.8epss 0.01

    XM^online 2 Common Utils and Endpoints 0.2.1 allows SQL injection, related to Constants.java, DropSchemaResolver.java, and SchemaChangeResolver.java.

  • CVE-2019-15557CriAug 26, 2019
    risk 0.00cvss 9.8epss 0.02

    XM^online 2 User Account and Authentication server 1.0.0 allows SQL injection via a tenant key.

  • CVE-2019-15555CriAug 26, 2019
    risk 0.00cvss 9.8epss 0.01

    FredReinink Wellness-app before 2019-06-19 allows SQL injection, related to dietTrack.php, exerciseGenerator.php, fitnessTrack.php, and server.php.

  • CVE-2019-15560CriAug 26, 2019
    risk 0.00cvss 9.8epss 0.01

    The Reviews Module before 2019-06-14 for OpenSource Table allows SQL injection in database/index.js.

  • CVE-2019-15559CriAug 26, 2019
    risk 0.00cvss 9.8epss 0.01

    DianoxDragon Hawn before 2019-07-10 allows SQL injection.

  • CVE-2019-15571CriAug 26, 2019
    risk 0.00cvss 9.8epss 0.01

    The WEB control panel before 2019-04-30 for ClonOS allows SQL injection in clonos.php.

  • CVE-2019-15569CriAug 26, 2019
    risk 0.00cvss 9.8epss 0.01

    HM Courts & Tribunals ccd-data-store-api before 2019-06-10 allows SQL injection, related to SearchQueryFactoryOperation.java and SortDirection.java.

  • CVE-2019-15568CriAug 26, 2019
    risk 0.00cvss 9.8epss 0.01

    idseq-web before 2019-07-01 in Infectious Disease Sequencing Platform IDseq allows SQL injection via tax_levels.

  • CVE-2019-15567CriAug 26, 2019
    risk 0.00cvss 9.8epss 0.01

    OpenForis Arena before 2019-05-07 allows SQL injection in the sorting feature.

  • CVE-2019-15566CriAug 26, 2019
    risk 0.00cvss 9.8epss 0.02

    The Alfresco application before 1.8.7 for Android allows SQL injection in HistorySearchProvider.java.

  • CVE-2019-15565CriAug 26, 2019
    risk 0.00cvss 9.8epss 0.01

    The ICOMMKT connector before 1.0.7 for PrestaShop allows SQL injection in icommktconnector.php.